Blackberry ENTERPRISE SOLUTION SECURITY - ENFORCING ENCRYPTION OF INTERNAL AND EXTERNAL FILE SYSTEMS ON DEVICES Guida Utente

Navigare online o scaricare Guida Utente per Software Blackberry ENTERPRISE SOLUTION SECURITY - ENFORCING ENCRYPTION OF INTERNAL AND EXTERNAL FILE SYSTEMS ON DEVICES. Blackberry ENTERPRISE SOLUTION SECURITY - ENFORCING ENCRYPTION OF INTERNAL AND EXTERNAL FILE SYSTEMS ON DEVICES User guide Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa

Sommario

Pagina 1 - Security Technical Overview

BlackBerry Enterprise SolutionVersion: 5.0 | Service Pack: 1Security Technical Overview

Pagina 3 - Contents

Process flow: Turning on two-factor authentication using a smart cardWhen you or a user turns on two-factor authentication with the BlackBerry® Smart

Pagina 4

Two-factor content protectionContent protection is designed to encrypt data on a BlackBerry® device when the BlackBerry device is locked. When you con

Pagina 5

Protecting Bluetooth connections on a BlackBerry deviceBluetooth® wireless technology permits a Bluetooth enabled BlackBerry® device to open a wireles

Pagina 6

Wi-Fi enabled BlackBerry devices16Wi-Fi® enabled BlackBerry® devices permit users with qualifying data plans to access BlackBerry services over a mobi

Pagina 7

Type Descriptionhome Wi-Fi networks A home Wi-Fi network uses a single access point to provide Internet access througha broadband gateway. The broadba

Pagina 8

Feature DescriptionBlackBerry transport layer encryption BlackBerry transport layer encryption is designed to encrypt messages that theBlackBerry devi

Pagina 9

Feature Descriptionwireless software updates Wireless software updates permits users to update the BlackBerry® Device Softwarewithout using the BlackB

Pagina 10

How an SSL connection between a Wi-Fi enabled BlackBerry device and the BlackBerryInfrastructure protects dataAn SSL connection between a Wi-Fi® enabl

Pagina 11 - Overview

• SSL_DH_anon_WITH_3DES_EDE_CBC_SHA• SSL_RSA_EXPORT_WITH_RC4_40_MD5• SSL_DH_RSA_EXPORT_WITH_DES40_CBC_SHA• SSL_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA• SSL_

Pagina 12

Managing how a BlackBerry device connects to an enterprise Wi-Fi networkTo manage how a Wi-Fi® enabled BlackBerry® device connects to an enterprise Wi

Pagina 13

Overview1BlackBerry Enterprise Solution securityThe BlackBerry® Enterprise Solution consists of various products and components that are designed to e

Pagina 14

After you configure a VPN, the BlackBerry device can use a layer 2 security method to connect to the enterprise Wi-Fi network,and use the VPN to provi

Pagina 15

Using a captive portal to connect to an enterprise Wi-Fi network or Wi-FihotspotA captive portal uses web-based authentication to permit a Wi-Fi® enab

Pagina 16

• permit the user to specify the software token PIN• configure the RSA SecurID to automatically generate and send a software token PIN to a Wi-Fi® ena

Pagina 17

Layer 2 security methods that a Wi-Fi enabled BlackBerrydevice supports17You can configure a Wi-Fi® enabled BlackBerry® device to use security methods

Pagina 18 - New in this release

PSK protocolThe IEEE® 802.1X™ standard specifies the PSK protocol as an access control method for enterprise Wi-Fi® networks. You canalso use the PSK

Pagina 19 - Keys on a BlackBerry device

Process flow: Authenticating a Wi-Fi enabled BlackBerry device with an enterprise Wi-Finetwork using the IEEE 802.1X standardIf you configured a wirel

Pagina 20

PEAP authenticationPEAP authentication permits a Wi-Fi® enabled BlackBerry® device to authenticate with an authentication server and access anenterpri

Pagina 21 - Device transport keys

EAP-FAST authenticationEAP-FAST authentication uses PAC to open a TLS connection to a Wi-Fi® enabled BlackBerry® device and verify the supplicantcrede

Pagina 22

• EAP-TTLS authentication• PEAP authentication• PSK authenticationFor more information about AES-CCMP and TKIP, visit www.ieee.org/portal/site.EAP aut

Pagina 23

Protecting a third-party application on a BlackBerry device18Creating a third-party application for a BlackBerry deviceA developer can create a third-

Pagina 24 - 4.0 or later

Security features of the BlackBerry Enterprise SolutionFeature Descriptiondata protection The BlackBerry® Enterprise Solution is designed to protect d

Pagina 25

• User Authenticator API, which permits the registration of drivers so that a user can unlock the BlackBerry device using two-factor authenticationYou

Pagina 26 - Message keys

Permitting a third-party application to encode data on a BlackBerry deviceA developer can use the Transcoder API to create an encoding scheme for data

Pagina 27 - Content protection keys

RIM Cryptographic API19The RIM® Cryptographic API that is on a BlackBerry® device and in the BlackBerry® Java® Development Environment consistsof a Ja

Pagina 28

The RIM Cryptographic API supports the ECIES algorithm, with an unlimited key length (160 bits to 571 bits for seeding), as theasymmetric stream encry

Pagina 29 - Principal encryption keys

Key generation algorithms that the RIM Cryptographic API supportsAlgorithm Key length (bits) TypeDiffie-Hellman 512 to 4096 discrete logarithmDSA 512

Pagina 30 - PIN encryption keys

Cipher suites for the key establishment algorithm that the RIM Cryptographic API supportsDirect mode SSL Direct mode TLS WTLSDH_anon DH_anon RSA® _768

Pagina 31

Limitations of RIM Cryptographic API support for cipher suites for the keyestablishment algorithmThe RIM® Cryptographic API implementation of the TLS

Pagina 32

Related resources20Resource InformationBlackBerry Enterprise Server Featureand Technical Overview• understanding BlackBerry® Enterprise Server archite

Pagina 33

Resource InformationEnforcing Encryption of Internal andExternal File Systems on BlackBerryDevices Technical Overview• understanding which data items

Pagina 34

Glossary213GPPThird Generation Partnership ProjectAESAdvanced Encryption StandardAES-CCMPAdvanced Encryption Standard Counter Mode CBCMAC ProtocolANSI

Pagina 35

Architecture: BlackBerry Enterprise SolutionThe BlackBerry® Enterprise Solution consists of various components that permit you to extend your organiza

Pagina 36

BlackBerry inter-process protocol encryption encrypts communication between BlackBerry® Enterprise Solution componentsto prevent other parties from vi

Pagina 37

code-signing keysCode-signing keys are the keys that are stored on media cards that sign files so that a user can install and run the files ona BlackB

Pagina 38

EAPExtensible Authentication ProtocolEAPoLExtensible Authentication Protocol over LANEAP-FASTExtensible Authentication Protocol Flexible Authenticatio

Pagina 39 - BlackBerry device

ECMQVElliptic Curve Menezes-Qu-VanstoneECNRElliptic Curve Nyberg RueppelEDEEncryption-Decryption-EncryptionEDGEEnhanced Data Rates for Global Evolutio

Pagina 40

General Services AdministrationGSMGlobal System for Mobile communications®HMACkeyed-hash message authentication codeHTTPHypertext Transfer ProtocolHTT

Pagina 41 - BlackBerry device memory

IT policy ruleAn IT policy rule permits you to customize and control the actions that BlackBerry devices, BlackBerry enabled devices, theBlackBerry® D

Pagina 42

MIDPMobile Information Device ProfileMMSMultimedia Messaging ServiceMS-CHAPMicrosoft Challenge Handshake Authentication ProtocolNATnetwork address tra

Pagina 43

PFSPerfect Forward Secrecypersistent store in flash memoryThe persistent store in flash memory stores data for a BlackBerry device. By default, third-

Pagina 44

RFCRequest for CommentsRIM signing authority systemThe RIM® signing authority system is a collection of servers that sign the boot ROM code for a Blac

Pagina 45

SRP authenticationSRP authentication is an authentication method that the BlackBerry® Enterprise Server and BlackBerry® Infrastructure useto authentic

Pagina 46

Component DescriptionBlackBerry Administration Service The BlackBerry Administration Service is a BlackBerry® Enterprise Servercomponent that connects

Pagina 47

WLANwireless local area networkWPAWi-Fi Protected AccessWTLSWireless Transport Layer SecuritySecurity Technical OverviewGlossary138

Pagina 48

Provide feedback22To provide feedback on this deliverable, visit www.blackberry.com/docsfeedback.Security Technical OverviewProvide feedback139

Pagina 49

Legal notice23©2009 Research In Motion Limited. All rights reserved. BlackBerry®, RIM®, Research In Motion®, SureType®, SurePress™ andrelated trademar

Pagina 50

HEREBY EXCLUDED. YOU MAY ALSO HAVE OTHER RIGHTS THAT VARY BY STATE OR PROVINCE. SOME JURISDICTIONSMAY NOT ALLOW THE EXCLUSION OR LIMITATION OF IMPLIED

Pagina 51

thereto. Your use of Third Party Products and Services shall be governed by and subject to you agreeing to the terms of separatelicenses and other agr

Pagina 52

Component DescriptionBlackBerry Device Software The BlackBerry Device Software consists of applications on a BlackBerry device thatpermit the user to

Pagina 53

Component DescriptionBlackBerry® MDS Studio The BlackBerry MDS Studio can be used by your organization's developers to createBlackBerry MDS Runti

Pagina 54 - Device Software

Component DescriptionBlackBerry® Smart Card Reader The BlackBerry Smart Card Reader controls access to your organization's sensitivecommunication

Pagina 55

New in this release2This document describes the security features that the BlackBerry® Enterprise Server version 5.0 SP1, BlackBerry® DesktopSoftware

Pagina 56

Keys on a BlackBerry device3The BlackBerry® Enterprise Solution generates keys that are designed to protect the data that is stored on a BlackBerry de

Pagina 57

SWD-847262-1028044248-001

Pagina 58

Key DescriptionECC public key The ECC public key encrypts the stored data that the BlackBerry device receiveswhen the BlackBerry device is locked.ephe

Pagina 59

State Descriptionpending A pending device transport key is the device transport key that the BlackBerryEnterprise Solution generates to replace the cu

Pagina 60

A BlackBerry device stores the device transport keys in a key store database in flash memory. The key store database is designedto prevent a potential

Pagina 61

If a user activates the BlackBerry device over the wireless network, the BlackBerry® Enterprise Server and BlackBerry devicenegotiate to select the st

Pagina 62

For more information about the ECMQV key exchange algorithm, see NIST: Special Publication 800-56: Recommendation onKey Establishment schemes, Draft 2

Pagina 63

To generate the device transport key, the BlackBerry Desktop Software performs the following actions:1. prompts the user to move the cursor2. uses the

Pagina 64

c. uses the SHA-1 function to hash the 256 bitsd. generates the device transport key of the BlackBerry device using the first 128 bits of the hashMess

Pagina 65

8. uses the pseudo-random bits with AES encryption or Triple DES encryption to generate the message keyFor more information about the DSA PRNG functio

Pagina 66 - Integration Service

Process flow: Turning on content protection using a BlackBerry Enterprise ServerYou can turn on content protection using a BlackBerry® Enterprise Serv

Pagina 67

The content protection key is a semi-permanent key that uses AES-256 encryption. If the user changes the BlackBerry devicepassword, the BlackBerry dev

Pagina 68

Contents1 Overview...

Pagina 69

Process flow: Generating a principal encryption keyWhen you or a user turns on content protection for device transport keys on a BlackBerry® device fo

Pagina 70

Encrypting data that the BlackBerry Enterprise Server anda BlackBerry device send to each other4To encrypt data that is in transit between the BlackBe

Pagina 71

A traditional attack tries to exploit data that a cryptographic system stores or transmits. The potentially malicious user tries todetermine the key o

Pagina 72

The BlackBerry device masks the round keys with random values and any S-Box masks that the AES algorithm requires to work.Round keys are subkeys that

Pagina 73

b. decrypts the email message using the message keyc. decompresses the email messaged. displays the email message to the userProcess flow: Sending an

Pagina 74

Managing BlackBerry Enterprise Solution security5Using an IT policy to manage BlackBerry Enterprise Solution securityYou can use an IT policy to contr

Pagina 75

Sending an IT policy over the wireless networkIf your organization's environment includes C++ based BlackBerry® devices that are running BlackBer

Pagina 76

IT administration command Description• require the BlackBerry device to return to its factory default settings when itreceives this command• specify w

Pagina 77

e. uses K to decrypt the content protection keyf. permanently deletes K5. The BlackBerry device performs the following actions:a. selects d randomlyb.

Pagina 78

Using a segmented network architecture to prevent the spread of malwareTo help prevent the spread of malware in your organization’s network, you can u

Pagina 79

Using IT policy rules to manage BlackBerry Enterprise Solution security... 33Sendi

Pagina 80

Best practice DescriptionControl which application on theBlackBerry device can use the GPSfeature.Consider preventing a third-party application or pre

Pagina 81

BlackBerry device memory6The BlackBerry® device memory consists of various sections that store user data and sensitive information such as keys. Third

Pagina 82

To change when the memory cleaner application runs, you can use IT policies or the BlackBerry device user can turn on or turnoff the memory cleaner ap

Pagina 83

Deleting all device data from the BlackBerry device memoryA BlackBerry® device is designed to permanently delete the following data from the NV store,

Pagina 84

• You click the Remove user data from current device option in the BlackBerry Administration Service after you connect theBlackBerry device to the Bla

Pagina 85

Process flow: Deleting all device data from a BlackBerry deviceThe following actions occur when you or a user delete all device data.1. The BlackBerry

Pagina 86

Scrubbing the BlackBerry device heap in RAM when deleting all BlackBerry device dataTo overwrite the BlackBerry® device heap that is in RAM for a Blac

Pagina 87

Scrubbing the user files on a BlackBerry device when deleting all BlackBerry device dataIf a BlackBerry® device supports a partition of flash memory t

Pagina 88

Protecting data on a BlackBerry device7Encrypting user data on a locked BlackBerry deviceIf you or a BlackBerry® device user turns on content protecti

Pagina 89

The BlackBerry device uses the BlackBerry device password to generate an ephemeral key that the BlackBerry device uses toencrypt the content protectio

Pagina 90

Process flow: Generating an encryption key for a media card... 5

Pagina 91 - S/MIME encryption algorithms

Encrypting the device transport key on a locked BlackBerry deviceIf you turn on content protection for device transport keys, a BlackBerry® device use

Pagina 92

Resetting a BlackBerry device password when content protection is turnedonIf you or a user turns on content protection for a BlackBerry® device that i

Pagina 93

Uppercase parameters represent elliptic curve points. Lowercase parameters represent scalars. The elliptic curve group operationsare additive.Paramete

Pagina 94

• generate random passwords that are designed to improve password strength• copy passwords and paste them into an application or password prompt for a

Pagina 95

How the BlackBerry Attachment Service protects data on a BlackBerry deviceA BlackBerry® device uses the BlackBerry Attachment Service to process an at

Pagina 96

code for a BlackBerry device during the manufacturing process, uses an RSA® public key to sign the boot ROM code. The processoris configured during th

Pagina 97

Protecting the data that the BlackBerry Enterprise Solutionstores in your organization's environment8Where the BlackBerry Enterprise Server store

Pagina 98 - Bluetooth connections

• name of each BlackBerry® Enterprise Server• unique SRP authentication keys and unique SRP IDs, or UIDs, that each BlackBerry Enterprise Server uses

Pagina 99

Best practice DescriptionMicrosoft SQL Server permits the sa account and, in some cases, other user accountsto access operating system calls based on

Pagina 100 - Two-factor authentication

Best practice Description• Use Microsoft SQL Server Management Studio to change the account that isassociated with a Microsoft SQL Server service, if

Pagina 101 - Two-factor content protection

What happens to data that is not delivered because a BlackBerry device is not available on the wireless network...

Pagina 102

Protecting communication with a BlackBerry device9Opening a direct connection between a BlackBerry device and a BlackBerryRouterA BlackBerry® Router a

Pagina 103 - Types of Wi-Fi networks

Closing a direct connection between a BlackBerry device and BlackBerry RouterIf a user disconnects a BlackBerry® device from a computer that hosts the

Pagina 104

Because the BlackBerry Router protocol can proceed past the point that it detects corrupted data, the BlackBerry Router protocolis unsuccessful at com

Pagina 105

b. sends RD and a device transport key identifier (KeyID) to the BlackBerry Enterprise Server3. The BlackBerry Router performs the following actions:a

Pagina 106 - Infrastructure

d. sends yB to the BlackBerry device9. One of the following actions occurs:• The BlackBerry Enterprise Server and BlackBerry device open an authentica

Pagina 107

Best practice: Protecting unsecured wireless messaging on the BlackBerrydeviceUnsecured wireless messaging includes SMS text messages, MMS messages, a

Pagina 108

Best practice DescriptionRequire a user to verify whether the userwants to send a message.Consider configuring the BlackBerry device so that the user

Pagina 109

The BlackBerry MDS security protocol uses a session key to authenticate data that the BlackBerry device sends to the BlackBerryMDS Integration Service

Pagina 110

The BlackBerry MDS security protocol uses AES-128 in CBC mode with PKCS #5 padding to encrypt and decrypt data that aBlackBerry device and BlackBerry

Pagina 111

What happens to data that is not delivered to a BlackBerry deviceWhat happens to data that is not delivered because the connection between a BlackBerr

Pagina 112

Updating the BlackBerry Device Software from an update web site...

Pagina 113 - WEP encryption

Protecting BlackBerry Enterprise Solutioncommunications in your organization's environment10How a BlackBerry Enterprise Server and the BlackBerry

Pagina 114 - IEEE 802.1X standard

How the BlackBerry Enterprise Solution protects a TCP/IP connection between a BlackBerryEnterprise Server and the BlackBerry InfrastructureAfter a Bla

Pagina 115 - LEAP authentication

If the BlackBerry Infrastructure rejects the challenge response, the authentication process is not successful. The BlackBerryInfrastructure and BlackB

Pagina 116 - EAP-TTLS authentication

Messaging server DescriptionThe BlackBerry Enterprise Server connects to a user’s mailbox in a highly securemanner using the trusted application key.

Pagina 117 - EAP-SIM authentication

Process flow: Authenticating the application loader tool or Roxio Media Manager with theBlackBerry Desktop Software using the BlackBerry inter-process

Pagina 118 - CCKM with

Activating a BlackBerry device11When a user activates a BlackBerry® device, the BlackBerry® Enterprise Solution authenticates the user and associates

Pagina 119

4. The BlackBerry Enterprise Server and BlackBerry device use the initial key establishment protocol to generate a devicetransport key and verify it.

Pagina 120

Enrolling certificates on a BlackBerry device over thewireless network12You can configure the BlackBerry® Enterprise Server to permit a BlackBerry dev

Pagina 121

9. The BlackBerry Enterprise Server sends the certificate chain to the BlackBerry device.10. The BlackBerry MDS Connection Service sends a status upda

Pagina 122 - RIM Cryptographic API

9. The BlackBerry Enterprise Server sends the certificate chain to the BlackBerry device.10. The BlackBerry MDS Connection Service sends a status upda

Pagina 123

Creating two-factor authentication methods...

Pagina 124

8. The BlackBerry Enterprise Server sends the certificate chain to the BlackBerry device.9. The BlackBerry MDS Connection Service sends a status updat

Pagina 125

Protecting BlackBerry Device Software updates13Protecting BlackBerry Device Software updates over the wireless networkYou can update the BlackBerry® D

Pagina 126

• requires the user to type the BlackBerry device password before the BlackBerry Device Software update process can backup or restore user data• requi

Pagina 127 - Related resources

During the update process, a BlackBerry device activates itself automatically over the wireless network so that the user can usea computer that is out

Pagina 128

Process flow: Generating a BlackBerry services key that protects cryptographic services dataThe BlackBerry® device uses an ephemeral AES-256 encryptio

Pagina 129 - Glossary

Process flow: Restoring cryptographic services data using the BlackBerry Desktop Manageror BlackBerry Application Web Loader1. After the update proces

Pagina 130

Extending messaging security to a BlackBerry device14If your organization's messaging environment supports highly secure messaging technology suc

Pagina 131

Key DescriptionPGP public key The PGP Support Package for BlackBerry smartphones uses the PGP public key ofthe recipient to encrypt outgoing email mes

Pagina 132

The PGP public key of the recipient indicates which encryption algorithm the recipient’s email application supports, and theBlackBerry device is desig

Pagina 133

Process flow: Receiving a PGP encrypted messageIf a recipient installs the PGP® Support Package for BlackBerry® smartphones on a BlackBerry device, th

Pagina 134

EAP authentication methods that a Wi-Fi enabled BlackBerry device supports... 113LEA

Pagina 135

The BlackBerry device user uses the S/MIME private key to decrypt S/MIME-protected messages on the BlackBerry device andto sign, encrypt, and send S/M

Pagina 136

Item DescriptionS/MIME private key When a user sends a signed email message or signed PIN message from a BlackBerrydevice, the BlackBerry device hashe

Pagina 137

Process flow: Sending an email message using S/MIME encryptionIf a sender installs the S/MIME Support Package for BlackBerry® smartphones on a BlackBe

Pagina 138

Process flow: Receiving an S/MIME-encrypted email messageIf a recipient installs the S/MIME Support Package for BlackBerry® smartphones, the BlackBerr

Pagina 139

In BlackBerry Enterprise Server version 5.0 or later and BlackBerry® Device Software version 5.0 or later, a BlackBerry deviceuser can encrypt message

Pagina 140

The BlackBerry Messaging Agent deletes the Lotus Notes .id file and the plain-text password when the BlackBerry® EnterpriseServer cannot decrypt a mes

Pagina 141 - Provide feedback

Process flow: Receiving an IBM Lotus Notes encrypted message1. A user uses the IBM® Lotus Notes® application on the user’s computer to encrypt a messa

Pagina 142 - Legal notice

Process flow: Viewing an attachment in a PGP encrypted message or S/MIME-encryptedmessageThe S/MIME Allowed Encrypted Attachment Mode IT policy rule o

Pagina 143

Configuring two-factor authentication and protectingBluetooth connections15BlackBerry Smart Card ReaderThe BlackBerry® Smart Card Reader is an accesso

Pagina 144

To control how a BlackBerry device can use an Advanced Security SD card, you can use the Force Smart Card Two-FactorAuthentication IT policy rule, For

Commenti su questo manuale

Nessun commento